logo

New PCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB for Credential Theft

ID: e05efb6d-0a81-5de8-990b-c0517eca4756

STIX ID: report--e05efb6d-0a81-5de8-990b-c0517eca4756

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Tushar Subhra Dutta

...
...

PCPJack is a sophisticated cloud-targeting worm and credential stealer that scans Common Crawl hostnames to discover exposed Docker, Kubernetes, Redis, MongoDB and other services, exploits multiple public CVEs to gain access, harvests SSH keys, API tokens, database credentials and wallet files, encrypts exfiltrated data with X25519/ChaCha20-Poly1305 and sends it via Telegram, and deploys multi-architecture Sliver backdoors for persistence; the report from SentinelOne includes detailed technical analysis, IoCs, and recommended mitigations such as enforcing MFA and securing container and cloud APIs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.